Apache / Axis
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-51441 | Apache Axis 1.x (EOL) may allow SSRF when untrusted input is passed to the service admin HTTP API | HIGH | 7.2 | Jan 6, 2024 |
| CVE-2023-40743 | Apache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getService | CRITICAL | 9.3 | Sep 5, 2023 |
| CVE-2019-0227 | axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution. | HIGH | 7.5 | May 1, 2019 |
| CVE-2018-8032 | axis: cross-site scripting (XSS) attack in the default servlet/services | MEDIUM | 6.1 | Aug 2, 2018 |
| CVE-2014-3596 | axis: SSL hostname verification bypass, incomplete CVE-2012-5784 fix | MEDIUM | 5.8 | Aug 27, 2014 |
| CVE-2012-5784 | axis: missing connection hostname check against X.509 certificate name | MEDIUM | 5.8 | Nov 4, 2012 |
| CVE-2007-2353 | Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resu… | MEDIUM | 5.3 | Apr 30, 2007 |
Showing 1 to 7 of 7 CVEs